Key findings:
A systemic flaw at the core of MCP.
A design choice in the Model Context Protocol’s STDIO handling enabled unauthenticated command injection and full takeover.
The risk moved downstream, silently.
Anthropic, LangChain, and FastMCP all responded “by design.” The risk didn’t disappear, it shifted to users.
AI-era shadow IT is invisible and highly privileged.
9 of 11 MCP marketplaces accepted a malicious server with no review; only GitHub’s managed registry blocked it.
Unified platform context.
MCP servers access source code, API keys, databases, and private conversations, often outside any inventory.
If you don’t know which MCP-enabling tools are running in your developer environment right now, this report is for you.
OX Security research coordinated 30+ disclosures across the MCP ecosystem, uncovering 10+ CVEs and 200+ affected open-source projects. The core issue is a critical, systemic vulnerability at the heart of MCP, and vendor responses of “by design” mean the exposure is now a downstream problem for the organizations that adopted these tools.
Inside the report: 6 insights and what to do
- Responsibility tends to shift. When vendors respond “by design,” risk moves downstream silently. Build a process for surfacing unresolved upstream vulnerabilities.
- Open source is accumulating unpaid security debt. 9 of 11 marketplaces accepted a malicious server; many maintainers didn’t respond for weeks. Prefer commercially-backed dependencies; flag OSS critical-issue response over 30 days as high-risk.
- Not all marketplaces are equal. Only GitHub’s managed registry blocked the malicious submission. Maintain an approved registry list; block unapproved sources.
- IDE security posture varies widely. Windsurf allowed zero-click RCE; Copilot showed an explicit warning. Audit IDEs in use; standardize on tools that warn on MCP config changes.
- AI tool adoption requires dedicated governance. LangFlow, GPT Researcher, and LettaAI all exposed STDIO with no sanitization. Establish an AI integration intake process; flag STDIO as high-risk.
- AI-era shadow IT is invisible and highly privileged. MCP servers reach source code, keys, databases, and private conversations. Scan for processes communicating over STDIO or known MCP ports.
By the numbers:
150M+ downloads exposed.
200K+ exposed servers.
10+ CVEs and counting.
30+ coordinated disclosures • 200+ affected OSS projects • 11 marketplaces tested, 9 failed.